![Mastering Identity and Access Management with Microsoft Azure](https://wfqqreader-1252317822.image.myqcloud.com/cover/884/36698884/b_36698884.jpg)
Configure dynamic group memberships
In the next section, we will configure straightforward dynamic group memberships to use the department attribute to add users to their department group and build up a dynamic licensing assignment. Group-based licensing currently does not support groups that contain other groups (nested groups).
When enabling dynamic groups, current memberships will be lost.
The usage location of a user needs to be set to assign a license.
As the admin@domain.onmicrosoft.com, choose the Accounting group, navigate to properties, and change the membership type to Dynamic User.
Create a simple rule, department Equals (-eq) Accounting:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/b4e98202-681e-4998-9b18-a171ae9dabff.png?sign=1739300949-bWEhwBI2WcaVXYwqE0NhOpO5HdMelufz-0-c85d00cd9090a1036d90489e1888545a)
Set the department attribute (profile section) on the accounting users Brian Cox and Jeff Simpson to Accounting:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/bb725e0d-f542-4984-8e69-4b552a9e2d0e.png?sign=1739300949-FTykpZN2Uo5olVg0N8hQj7hWPk0k4GNn-0-b4cc3cdb80c408ba6c14aaa06a2d6c83)
The member should be added automatically. Check the group membership and verify the two new members:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/22c71e10-5bd3-4b5c-8ad3-c0b720b3a30a.png?sign=1739300949-wB6Kp1QWMsupcKLXCAejJdlVSKEFGx0x-0-3aa3a535a55ce93504051126a4b3d0c1)
Next, we will provide an automatic licensing solution.
Create the following security group:
- Office 365 full feature licensing
- Group description: Automatic Office 365 Full Feature Licensing
- Membership type: Dynamic User
- Dynamic query: userType -eq Member:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/c4c4cd37-530e-409e-8cb5-47e34850a679.png?sign=1739300949-R9nbyJBMUI2jLLfO3tXWelAA5GX7OiD1-0-5d81e9d1acdca078d88c8ca3022745ef)
Under Licenses | Products, assign the Office 365 E5 plan. Don't choose any assignment options at the moment:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/562b5fba-363c-4973-ab41-77e714912df3.png?sign=1739300949-DRUHlMtYFcmYijBt2w7sissclCIHeSGv-0-097e7d597dcee7ef2cd9f87099fd98b1)
Wait until the membership has updated and check the license assignment for Don.Hall@domain.onmicrosoft.com.
You will see that the user gets the license through a direct and group-based assignment:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/ee6dd666-83d0-46e9-919b-1406451e37a4.png?sign=1739300949-rR3oPVEVdr0iyZRToLyZUNLPy4XxELoA-0-7cdc3af464596970a1f08d119f7f4c80)
In the next section, we will configure role assignments to administrative units.